What a Business Associate Agreement Actually Means for Your AI Vendor
What a Business Associate Agreement Actually Means for Your AI Vendor
There is one document that separates a healthcare operator who is legally protected from one who is exposed.
Most operators have heard of it. Few have read it. Almost none ask for it before they start a vendor conversation.
It's called a Business Associate Agreement — a BAA — and if you are deploying any AI system that touches Protected Health Information in your practice, it is not optional. It is not a formality. It is the legal foundation that determines who is accountable when something goes wrong.
This post is a practical guide to what a BAA actually is, what it needs to contain, how to evaluate whether your AI vendor can sign one, and what to do when they can't.
What a Business Associate Agreement Is
Under HIPAA, a Business Associate is any person or organization that performs functions or activities on behalf of a covered entity that involve the use or disclosure of Protected Health Information.
In plain language: if a vendor's system touches your patient data — even in transit, even temporarily, even as metadata — they are a Business Associate. And before that relationship begins, a signed BAA must be in place.
The BAA is a contract between the covered entity (your practice) and the Business Associate (the vendor). It defines:
- What PHI the vendor is permitted to access, use, and disclose
- The purposes for which the vendor may use that PHI
- The security safeguards the vendor is required to maintain
- What happens in the event of a breach — who reports, to whom, and within what timeframe
- The vendor's obligation to ensure their own subcontractors are also bound by equivalent BAA terms
- What happens to PHI when the relationship ends — return, destruction, or documented retention with continued protections
Without a signed BAA, your practice is operating outside HIPAA requirements the moment that vendor touches PHI. That exposure is yours, not the vendor's — unless the BAA is in place to shift appropriate accountability.
Why AI Vendors Are a Specific Risk
Traditional software vendors serving healthcare have had years to mature their BAA processes. Most EHR vendors, billing platforms, and practice management systems have standard BAAs ready to execute.
AI vendors are a different situation.
The AI industry has moved faster than its compliance infrastructure. Many AI platforms — including some actively marketing to healthcare — are built on general-purpose cloud infrastructure that has not been assessed for HIPAA eligibility. Their terms of service frequently include broad rights to use customer data for model training. Their support documentation may reference HIPAA compliance without specifying whether a BAA is actually available.
This creates a specific risk pattern for healthcare operators: a vendor that appears credible, uses the right language, and may genuinely believe their product is appropriate for healthcare — but cannot actually execute a compliant BAA because their underlying infrastructure hasn't been built to support it.
The consequences of getting this wrong are significant. HIPAA penalties range from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category. In breach scenarios, the covered entity bears primary accountability. A vendor that cannot sign a BAA is not a vendor you can use for PHI workflows, regardless of how good their product is.
The Four Questions to Ask Before Any AI Vendor Demo
Before you sit through a product demonstration, before you discuss pricing, before you sign a non-disclosure agreement, ask these four questions. The answers will tell you everything you need to know.
"Will you sign a Business Associate Agreement?"
This is binary. Yes or no. If the answer is anything other than an immediate yes, that vendor cannot handle PHI in your environment. Note the difference between "we are HIPAA compliant" and "we will sign a BAA." The first is a marketing claim. The second is a legal commitment.
"Where is PHI stored, and is that infrastructure HIPAA-eligible?"
HIPAA-eligible infrastructure means the underlying cloud or server environment has been specifically assessed and configured to meet HIPAA technical safeguard requirements. AWS, Google Cloud, and Microsoft Azure all offer HIPAA-eligible configurations — but not all services within those platforms are HIPAA-eligible by default. Ask for specifics, not general claims.
"Is customer data used to train your AI models?"
Many AI systems improve their models using data processed through the platform. For general business applications, this is often an acceptable trade-off. For PHI, it is categorically incompatible with HIPAA. A vendor whose terms of service permit model training on customer data cannot handle PHI — full stop. Get a written confirmation that PHI is not used for model training.
"Can you provide your subcontractor BAA chain?"
Your BAA with the vendor is only as strong as the vendor's BAAs with their own subcontractors. If your vendor uses a cloud provider, an analytics platform, or any third-party service that touches PHI, those subcontractors must also be bound by equivalent BAA terms. Ask for documentation of the full chain.
What a Strong BAA Contains
Not all BAAs are equal. A vendor that will sign a BAA is a better starting point than one that won't — but the content of the agreement matters as much as its existence.
A compliant, protective BAA should include:
Permitted uses and disclosures — specific, limited language defining exactly what the vendor may do with PHI. Broad language like "as necessary to provide services" is a flag. Specific language defining the exact functions and limiting use to those functions is what you want.
Safeguard requirements — explicit reference to the HIPAA Security Rule administrative, physical, and technical safeguard requirements. The vendor should be contractually obligated to maintain these, not merely encouraged.
Breach notification timeline — HIPAA requires notification of a breach without unreasonable delay and within 60 days of discovery. Your BAA should specify the vendor's obligation to notify you promptly — ideally within 24–72 hours of discovery — so you can meet your own notification obligations.
Subcontractor obligations — the vendor must ensure that any subcontractor who receives PHI from them is bound by the same restrictions and conditions. This should be explicit in the BAA, not assumed.
Return or destruction of PHI — when the relationship ends, the BAA must address what happens to PHI. Return to the covered entity, destruction with certification, or continued protection with documented justification for retention. "We'll delete it" is not sufficient without a contractual obligation and a timeline.
Audit rights — you should have the right to audit the vendor's compliance with the BAA, or at minimum require the vendor to provide compliance documentation on request. Many vendors will push back on direct audit rights — at minimum, require annual confirmation of continued compliance.
When the Vendor Can't Sign
If a vendor you want to work with cannot sign a BAA, you have three options.
Option 1 — Design around PHI. Many AI workflows can be architected to operate without touching PHI directly. A patient intake agent that qualifies prospective patients before they become patients, an appointment reminder that confirms date and time without referencing clinical information, a referral tracking workflow that operates on scheduling data rather than clinical records — none of these require PHI access. If the vendor's platform is strong and their inability to sign a BAA is a current limitation rather than a fundamental architecture problem, it may be worth working with them on non-PHI workflows while your PHI workflows are handled on compliant infrastructure.
Option 2 — Wait for their compliance roadmap. Some AI vendors are actively building toward HIPAA eligibility. If a vendor is transparent about where they are in that process and can provide a credible timeline, it may be worth maintaining the relationship for non-PHI use cases while they complete the work.
Option 3 — Find a vendor that can. This is frequently the right answer. The AI vendor landscape is large and growing. If a vendor cannot sign a BAA and PHI access is a requirement for the workflow you need to automate, work with someone who has done the compliance work. The operational benefits of AI follow-up automation, clinical documentation support, or care gap analysis are not exclusive to any single platform.
Building the Right Way From the Start
The practices that are successfully deploying AI in healthcare right now share a common characteristic: they treated compliance as architecture, not afterthought.
They identified their PHI workflows first. They confirmed BAA availability before vendor selection. They built on HIPAA-eligible infrastructure from the start rather than retrofitting compliance onto a system that wasn't designed for it. And they extended their AI capabilities incrementally — starting with the lowest-PHI workflows and building the compliance foundation as they went.
At AgenticWhispers, when we assess a healthcare client's AI readiness on MindStudio, the BAA question is one of the first items on the checklist. Not because it's the most interesting part of the work — it isn't — but because it determines what's possible. Getting it right at the start means everything built on top of it is on solid ground.
The compliance framework isn't the obstacle. It's the foundation.
Ready to Assess Your AI Vendor Stack?
If you're evaluating AI vendors for your healthcare practice and want a clear picture of what questions to ask, what the compliance requirements are, and what a responsible deployment looks like — that's exactly what a Whisper Session covers.
60 minutes. A concrete compliance and deployment roadmap for your specific practice. No pitch deck.
Book Your Whisper Session — $750
John Korf is the founder of AgenticWhispers and The Agent Shepherd. He builds and deploys human-led AI agent systems for healthcare, construction, insurance, and transportation organizations. His approach is grounded in 30+ years of international business experience and a commitment to keeping humans in the loop.
Shepherd the Future. Keep Humans in AI.



Comments
Post a Comment